Live data from Hacker News

WoSign and StartCom: Mozilla’s proposed conclusion

docs.google.com

61–70 of 252 posts

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#61
Well shit. I always liked StarCom because of their approach to charge for verification (with increasing costs for each higher trust level) but not for issuing certs (while still manually checking every cert request, at least for any OV&EV cert in my case). This entire WoSign acquisition is incredibly shady. Shortly after that some of the customer reps had chinese names, service quality declined and we got offered to become an "Intermediate CA" (StartPKI) for 10k$/yr.

What is the best alternative CA that also offers wildcard certificates (preferably with a similar business model)?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#62
post #40
post #33

Earlier quoted context omitted.

Mozilla is killing StartCom. Chrome has not announced a decision yet, although I predict that they will also distrust.

It's pertinent in this matter that one of the authors of the report works on the Chromium TLS stack. But it's not clear to me whether Chrome has an independent CA program. They use the Microsoft CA store on Windows, and at some point were using NSS (and hence the Mozilla certs) on Unixes. I presume they can always just additionally block this CA in Chrome, though.

Ryan Sleevi authored the report in his capacity as a peer of the Mozilla CA Certificates Module, not as a Chrome/Google employee. See https://wiki.mozilla.org/CA:Policy_Participants

Chrome does indeed use the platform CA store, but they can and do impose additional logic on top of it, such as requiring CT for Symantec, distrusting new CNNIC certs, or name-constraining ANSSI and India CCA.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#63
post #36
post #19

Earlier quoted context omitted.

Who cares if it's a pain? User security is vastly more important than saving companies from the mild inconvenience of changing certs.

You forget things like certificate pinning which can make sites inaccessible for long durations of time if the user doesn't visit said website during this transition period. I'm not super convinced about the user security argument either. Sure, they backdated SHA-1 certificates and that's nasty but those certificates still expire at a reasonable time in the near future and will soon enough not be accepted by browsers…

Mozilla and the other browser developers' position seems to be that issuing SHA-1 certificates when they've said SHA-1 certificates should not be issued is a cardinal sin - never mind that this would break payments infrastructure. They eventually agreed to an exception process after Tyro's payments systems would presumably have stopped working if WoSign hadn't issued them a certificate.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#64
post #39

While most of the doc focused on StartCom/WoSign, I thought this bit at the end was interesting: > no longer accept audits carried out by Ernst & Young (Hong Kong). To reject audits from E&Y.... It makes me wonder about the transparency and trust we put in the auditors as being a key part of CA validation process.

Auditors and ratings agencies and their ilk are a fundamentally broken service in our society. On the one hand they have to make money and on the other they have to be honest. The two are simply not compatible, seemingly. Eg: ratings agencies happily giving top tier ratings to mortgages back in pre 2008.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#65
post #39

While most of the doc focused on StartCom/WoSign, I thought this bit at the end was interesting: > no longer accept audits carried out by Ernst & Young (Hong Kong). To reject audits from E&Y.... It makes me wonder about the transparency and trust we put in the auditors as being a key part of CA validation process.

Isn't that only E&Y Hong Kong, though? Really at this point I don't know why anybody in China, or any country known for its corruption, should be accepted as auditors.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#66
TL;DR:

> Taking into account all the issues listed above, Mozilla’s CA team has lost confidence in the ability of WoSign/StartCom to faithfully and competently discharge the functions of a CA. Therefore we propose that, starting on a date to be determined in the near future, Mozilla products will no longer trust newly-issued certificates issued by either of these two CA brands.

I recommend reading the whole thing if you have time. They used some shady tactics.

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#67
post #10
post #5

This is a very detailed investigation - the parts that appear to be new are the specific serial number patterns, the times/dates of manual issuance, and the case of the Tyro SHA-1 cert. It's a little unfortunate that Mozilla's option here is to rely on WoSign and StartCom continuing to be honest about notBefore, or really, on Google detecting further abuse of notBefore via Certificate Transparency. Mozilla should rea…

> Google detecting further abuse of notBefore via Certificate Transparency You don't need to rely on Google. All certs issued by WoSign since January 1st, 2015 should be on WoSign's own Certificate Transparency log from which you can download them. StartCom is logging all new certs too, but I don't know for sure if they pushed all older ones too. If you ever encounter a cert that isn't on the list, that's definitive…

Why should we trust their list?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#69
post #51

Earlier quoted context omitted.

What exactly don't you like about Let's Encrypt? Besides Let's Encrypt, your other option is paying for a cert from GoDaddy or something. My two cents: don't give business to Comodo, given their horrible track record of sleaziness ( https://en.wikipedia.org/wiki/Comodo_Group#Controversies ).

I don't like the EFF, but I guess I will have to use Let's Encrypt if there's no other option.

If I might ask, why don't you like them?

Re: WoSign and StartCom: Mozilla’s proposed conclusion

#70
post #26
post #16

Mozilla and Chrome are killing StartCom. This is huge, isn't it? StartCom is one of the more popular CAs. Later: Additional fun fact: there's a decent-sized subthread on the mailing list in which it's strongly suggested that WoSign is itself quietly owned by Qihoo360, a much larger company --- somewhat like the Symantec of China. More specifically: https://twitter.com/pzb/status/780456712562024448

They're not "killing" anyone. They have reasonable doubt that the CA has misrepresented the truth and engaged in practices that violate the rules set forth by the CAB and those for inclusion in the Mozilla trust store. There will have to be consequences for else it means nothing. They're also very clear that they do not intend to invalidate any already issued certificates, only new ones after a specific, yet to be de…

A one year timeout seems likely to tank their business. "We can't renew your cert, you'll have to go elsewhere" isn't great PR.

That said, they deserve it.

Post reply on HN